CVE-2021-1770
published 2021-09-08CVE-2021-1770: A buffer overflow may result in arbitrary code execution. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A logic…
PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.75%
84.6th percentile
A buffer overflow may result in arbitrary code execution. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A logic issue was addressed with improved state management.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_14.5_and_ipados | — | — |
| apple | ios_and_ipados | >= unspecified < 14.5 | 14.5 |
| apple | ipados | < 14.5 | 14.5 |
| apple | iphone_os | < 14.5 | 14.5 |
| apple | macos | >= 11.0 < 11.3 | 11.3 |
| apple | macos | >= unspecified < 11.3 | 11.3 |
| apple | macos_big_sur | — | — |
| apple | tvos | < 14.5 | 14.5 |
| apple | tvos | >= unspecified < 14.5 | 14.5 |
| apple | watchos | < 7.4 | 7.4 |
| apple | watchos | >= unspecified < 7.4 | 7.4 |
| sap-cloud-sdk | core | >= 0 < 1.52.0 | 1.52.0 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2021-1770: iOS 14.5 and iPadOS 14.5
vendor_apple·2021-04-26·CVSS 9.8
CVE-2021-1770 [CRITICAL] CVE-2021-1770: iOS 14.5 and iPadOS 14.5
Apple Security Update: About the security content of iOS 14.5 and iPadOS 14.5
Product: iOS 14.5 and iPadOS
Version: 14.5
CVE: CVE-2021-1770
Component: Wi-Fi
Impact: A buffer overflow may result in arbitrary code execution
Description: A logic issue was addressed with improved state management.
Apple
CVE-2021-1770: macOS Big Sur 11.3
vendor_apple·2021-04-26·CVSS 9.8
CVE-2021-1770 [CRITICAL] CVE-2021-1770: macOS Big Sur 11.3
Apple Security Update: About the security content of macOS Big Sur 11.3
Product: macOS Big Sur
Version: 11.3
CVE: CVE-2021-1770
Component: Wi-Fi
Impact: A logic issue was addressed with improved state management
Description: A buffer overflow may result in arbitrary code execution.
GHSA
GHSA-hpj8-7jw7-hq79: A buffer overflow may result in arbitrary code execution
ghsa_unreviewed·2022-05-24
CVE-2021-1770 [CRITICAL] CWE-119 GHSA-hpj8-7jw7-hq79: A buffer overflow may result in arbitrary code execution
A buffer overflow may result in arbitrary code execution. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A logic issue was addressed with improved state management.
GHSA
Unauthorized access to data in @sap-cloud-sdk/core
ghsa·2021-11-10
CVE-2021-41251 [MEDIUM] CWE-200 Unauthorized access to data in @sap-cloud-sdk/core
Unauthorized access to data in @sap-cloud-sdk/core
### Impact
This affects applications on SAP Business Technology Platform that use the SAP Cloud SDK and enabled caching of destinations.
In some cases, when user information was missing, destinations were cached without user information, allowing other users to retrieve the same destination with its permissions.
By default, destination caching is disabled. If it is enabled the maximum lifetime is 5 minutes which limits the attack vector.
### Patches
The problem was fixed by #1769 and #1770. The security for caching has been increased. The changes are released in version 1.52.0.
### Workarounds
Disable destination caching (it is disabled by default).
### References
[destination cache API docs](https://sap.github.io/cloud-sdk/api/1.51.0/
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://support.apple.com/en-us/HT212317https://support.apple.com/en-us/HT212323https://support.apple.com/en-us/HT212324https://support.apple.com/en-us/HT212325https://support.apple.com/en-us/HT212317https://support.apple.com/en-us/HT212323https://support.apple.com/en-us/HT212324https://support.apple.com/en-us/HT212325
2021-09-08
Published